Networking-Blog

My WordPress Blog

Linux Iptables POSTROUTING

sudo iptables -vnL -t nat
sudo iptables -vnL -t nat –line-numbers
!
sudo iptables -t nat -D POSTROUTING 2
sudo iptables -A POSTROUTING 2 -t nat -s 192.168.1.0/255.255.255.0 -d 80.74.22.151 -j hml
sudo iptables -I POSTROUTING 11 -t nat -s 195.110.181.74 -d 172.20.0.0/16 -j ACCEPT
!
sudo iptables -I POSTROUTING -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
sudo iptables -I POSTROUTING -s 120.1.1.1/255.255.255.224 -o eth2 -j SNAT –to-source 1.1.1.1
!
!

When we have a linux vm solution in place :

Postrouting on VM through to Cisco Device…

sudo iptables -I POSTROUTING  -s 80.74.22.64/255.255.255.224 -d 109.231.196.34 -j ACCEPT

Cisco Router: on WAN IP = 80.74.22.64/32

ip nat inside source static tcp 172.16.24.1 5631 interface dialer 0 5631
ip nat inside source static udp 172.16.24.1 5632 interface dialer 0 5632
!
ip access-list extended 111
permit udp host 109.231.196.34 any eq 5632
permit tcp host 109.231.196.34 any eq 5631

Linux Iptables Output Chain

sudo iptables -I smtp_out 1 -p tcp -s 10.11.254.250 -d 0.0.0.0/0 –dport 25 -j ACCEPT
sudo iptables -I smtp_out 2 -p tcp -s 10.11.254.251 -d 0.0.0.0/0 –dport 25 -j ACCEPT
sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j LOG
sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j DROP

The below statement will log all deny traffic which needs to be entered before the deny statement.

sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j LOG

Run this command to see log messages:

sudo cat /var/log/messages | grep DST=25
sudo cat /var/log/messages | grep 217.154.157.250

Iptables Rules

less <filename> (reads a file)
vi <filename> (edits a file)

Local history file(s)

/.bash_history (records the last entries made, so less the file to read it)
/var/lib/iptables/rules-save (records the last entries saved in iptables)

Examples :

iptables -vnL  (lists the iptables ruleset)
iptables -vnL – t nat  (lists the iptables nat tables, i.e PREROUTING,POSTROUTING)

1. Inserts a rule in the INPUT chain at line 5 that allows 10.10.0.0/16 to 1.1.1.1

iptables -I INPUT 5 -s 10.10.0.0/16 -d 1.1.1.1 -j ACCEPT

2. Deletes the above rule :

iptables -D INPUT 5

-A will append the rule to the Chain, rather than insert it
-I will insert the rule to the Chain, rather than append it

3. REDIRECT port 80 traffic to port 8080

iptables -I PREROUTING 9 -t nat -s 1.1.1.1 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

4. Source NAT everything from 1.1.1.1 to go out as 2.2.2.2
iptables -I POSTROUTING 20 -t nat -s 1.1.1.1 -o eth1 -j SNAT –to-source 2.2.2.2

5.  Allows 1.1.1.1  to talk to our ranges and vpn box

iptables -I POSTROUTING 8 -t nat -s 1.1.1.1 -d 83.44.16.6 -j ACCEPT
iptables -I POSTROUTING 12 -t nat -s 1.1.1.1 -d 83.44.16.8/29 -j ACCEPT

6. /etc/init.d/iptables save (saves the changes made to iptables)

7. DNATs, SNATs and ports

-i eth1 (for in port)
-o eth1 (for out port)

–dport <port number> (destination port) –to <ip address> (NAT to an IP)

Examples :

Adds a rule in to POSTROUTING chain, to SNAT everything out of eth0 with a source address of 172.16.26.1 to 83.44.16.6

iptables -I POSTROUTING 6 -t nat -o eth0 -s 172.16.26.1 -j SNAT –to 83.44.16.6

8. Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201

iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201

9. Adds a rule in the FORWARD chain allowing everything from 10.10.1.2 with a destination tcp port of 25

iptables -I FORWARD -s 10.10.1.2 -p tcp –dport 25 -j ACCEPT

Iptables Show Commands

sudo iptables -nvL
sudo iptables -t nat -vnL unfiltered_web
sudo iptables -t nat -vnL PREROUTING
sudo iptables -vnL FORWARD
!

sudo iptables -t nat -vnL unfiltered_web –line-numbers

!
sudo tail -f /var/log/messages

Added a line in the input chain to allow access

iptables -I INPUT 9 -p tcp -s 93.97.239.164/31 -d 85.234.71.225 –dport 3389 -j ACCEPT
iptables -R INPUT 9 -p tcp -s 93.97.239.164/31 -d 85.234.71.225 –dport 3389 -j ACCEPT
This should give access to the RDP session.

iptables -I  = Insert Rule
iptables -R = Replace Rule

Delete an Entry :

sudo iptables -D INPUT 9

Monitor iptables :

watch sudo iptables -nvL INPUT
watch sudo iptables -nvL OUTPUT
watch sudo iptables -nvL FORWARD

Iptables Save

Saving iptables

If you were to reboot your machine right now, your iptables configuration would disappear.
Rather than type this each time you reboot, however, you can save the configuration,
and have it start up automatically.

Directory Path :

GENTOO = /var/lib/iptables/rules-save
OPENSWAN = /etc/sysconfig/iptables

To save the configuration, you can use

iptables-save
iptables-restore

Save your firewall rules to a file

iptables-save >/etc/iptables.rules

Restore Iptables:

iptables-restore < /etc/iptables.rules

Iptables Input Rules

INPUT Rule :

iptables -I INPUT -i eth0 -p tcp -m tcp –dport 5900 -j ACCEPT # vnc
iptables -A INPUT -i eth0 -p tcp -m tcp –dport 21 -j ACCEPT # ftp
iptables -A INPUT -i eth0 -p tcp -m tcp –dport 22 -j ACCEPT # ssh
iptables -A INPUT -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT # cifs
iptables -A INPUT -i eth0 -p tcp -m tcp –dport 139 -j ACCEPT # netbios-ssn
iptables -A INPUT -i eth0 -p udp -m udp –dport 137 -j ACCEPT # netbios-ns
iptables -I INPUT 2 -i eth0 -p udp -m udp –dport 138 -j ACCEPT # netbios-dgm

Drop everything else :

iptables -A INPUT -i eth+ -p udp -j DROP
iptables -A INPUT -i eth+ -p tcp -m tcp –syn -j DROP

Linux Iptables Flush Script

Launch gedit

Create a shell script (iptables_flush.sh) and copy paste the following lines:

 #!/bin/sh
echo “Flushing iptables rules…”
sleep 1
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT

save as:  iptables_flush.sh in root

Make the file executable

chmod +x iptables_flush.sh

and run the script:

./iptables_flush.sh